Re: [Full-disclosure] adobe.com important subdomain SQL injection again!

2010-12-20 Thread John Jester
Regarding appeal to futility. Flash has it's own programming language in it. On every OS. On i686, amd64 and now ARM. It stores your data in a local db. It's on every web page. How could you ask for more attack vectors? Sandboxing the plug-in from your system fixes it I believe. It's so futile

Re: [Full-disclosure] adobe.com important subdomain SQL injection again!

2010-12-20 Thread John Jester
No real clue how Adobe will counter Flash 5. Perhaps they can use it as an opportunity to trim the beast down. -Original Message- From: Victor Rigo To: full-disclosure@lists.grok.org.uk Sent: Mon, Dec 20, 2010 12:56 am Subject: Re: [Full-disclosure] adobe.com important subdom

[Full-disclosure] Windows is 100% self-modifying assembly code? (Interesting security theory)

2010-12-10 Thread John Jester Wilham Patrick III
From Andrew Auernheimer's Diary / irc memories: Windows is written in pure, self-modifying assembly code. Notice how you can install 15 gigs of data from a single Windows install DVD, which can only hold 5 gigs? This is because the code is dynamically generated to minimize attack vectors.